期刊文献+
共找到7篇文章
< 1 >
每页显示 20 50 100
An Enhanced Automated Signature Generation Algorithm for Polymorphic Malware Detection
1
作者 Ke Tang Ming-Tian Zhou Zhi-Hong Zuo 《Journal of Electronic Science and Technology》 CAS 2010年第2期114-121,共8页
Polymorphic malware is a secure menace for application of computer network systems because hacker can evade detection and launch stealthy attacks. In this paper, a novel enhanced automated signature generation (EASG... Polymorphic malware is a secure menace for application of computer network systems because hacker can evade detection and launch stealthy attacks. In this paper, a novel enhanced automated signature generation (EASG) algorithm to detect polymorphic malware is proposed. The EASG algorithm is composed of enhanced-expectation maximum algorithm and enhanced K-means clustering algorithm. In EASG algorithm, the fixed threshold value is replaced by the decision threshold of interval area. The false positive ratio can be controlled at low level, and the iterative operations and the execution time are effectively reduced. Moreover, the centroid updating is realized by application of similarity metric of Mahalanobis distance and incremental learning. Different malware group families are partitioned by the centroid updating. 展开更多
关键词 Index Terms -Entropy false positive ratio Mahalanobis distance polymorphie malware signature generation.
下载PDF
An Algorithm for Generation of Attack Signatures Based on Sequences Alignment
2
作者 Nan Li Chunhe Xia +1 位作者 Yi Yang HaiQuan Wang 《Journal of Software Engineering and Applications》 2008年第1期76-82,共7页
This paper presents a new algorithm for generation of attack signatures based on sequence alignment. The algorithm is composed of two parts: a local alignment algorithm-GASBSLA (Generation of Attack Signatures Based o... This paper presents a new algorithm for generation of attack signatures based on sequence alignment. The algorithm is composed of two parts: a local alignment algorithm-GASBSLA (Generation of Attack Signatures Based on Sequence Local Alignment) and a multi-sequence alignment algorithm-TGMSA (Tri-stage Gradual Multi-Sequence Alignment). With the inspiration of sequence alignment used in Bioinformatics, GASBSLA replaces global alignment and constant weight penalty model by local alignment and affine penalty model to improve the generality of attack signatures. TGMSA presents a new pruning policy to make the algorithm more insensitive to noises in the generation of attack signatures. In this paper, GASBSLA and TGMSA are described in detail and validated by experiments. 展开更多
关键词 ATTACK signatureS generation Sequence Local Alignment AFFINE PENALTY INTRUSION Detection PRUNING Policy
下载PDF
Generating Rule-Based Signatures for Detecting Polymorphic Variants Using Data Mining and Sequence Alignment Approaches
3
作者 Vijay Naidu Jacqueline Whalley Ajit Narayanan 《Journal of Information Security》 2018年第4期265-298,共34页
Antiviral software systems (AVSs) have problems in detecting polymorphic variants of viruses without specific signatures for such variants. Previous alignment-based approaches for automatic signature extraction have s... Antiviral software systems (AVSs) have problems in detecting polymorphic variants of viruses without specific signatures for such variants. Previous alignment-based approaches for automatic signature extraction have shown how signatures can be generated from consensuses found in polymorphic variant code. Such sequence alignment approaches required variable length viral code to be extended through gap insertions into much longer equal length code for signature extraction through data mining of consensuses. Non-nested generalized exemplars (NNge) are used in this paper in an attempt to further improve the automatic detection of polymorphic variants. The important contribution of this paper is to compare a variable length data mining technique using viral source code to the previously used equal length data mining technique obtained through sequence alignment. This comparison was achieved by conducting three different experiments (i.e. Experiments I-III). Although Experiments I and II generated unique and effective syntactic signatures, Experiment III generated the most effective signatures with an average detection rate of over 93%. The implications are that future, syntactic-based smart AVSs may be able to generate effective signatures automatically from malware code by adopting data mining and alignment techniques to cover for both known and unknown polymorphic variants and without the need for semantic (run-time) analysis. 展开更多
关键词 NNge Classifier Gap PENALTIES JS.Cassandra VIRUS POLYMORPHIC VIRUS Automatic signature generation Sequence Alignment SYNTACTIC Exploration
下载PDF
Random-injection-based two-channel chaos with enhanced bandwidth and suppressed time-delay signature by mutually coupled lasers: Proposal and numerical analysis 被引量:2
4
作者 许世蓉 贾新鸿 +3 位作者 马辉亮 林佳兵 梁文燕 杨玉莲 《Chinese Physics B》 SCIE EI CAS CSCD 2021年第1期239-247,共9页
Simultaneous bandwidth(BW) enhancement and time-delay signature(TDS) suppression of chaotic lasing over a wide range of parameters by mutually coupled semiconductor lasers(MCSLs) with random optical injection are prop... Simultaneous bandwidth(BW) enhancement and time-delay signature(TDS) suppression of chaotic lasing over a wide range of parameters by mutually coupled semiconductor lasers(MCSLs) with random optical injection are proposed and numerically investigated. The influences of system parameters on TDS suppression(characterized by autocorrelation function(ACF) and permutation entropy(PE) around characteristic time) and chaos BW are investigated. The results show that, with the increasing bias current, the ranges of parameters(detuning and injection strength) for the larger BW(> 20 GHz) are broadened considerably, while the parameter range for optimized TDS(< 0.1) is not shrunk obviously.Under optimized parameters, the system can simultaneously achieve two chaos outputs with enhanced BW(> 20 GHz)and perfect TDS suppression. In addition, the system can generate two-channel high-speed truly physical random number sequences at 200 Gbits/s for each channel. 展开更多
关键词 random distributed feedback-based optical injection two-channel chaos lasing bandwidth enhancement and time-delay signature suppression physical random number generation
下载PDF
Exploring the Effects of Gap-Penalties in Sequence-Alignment Approach to Polymorphic Virus Detection 被引量:1
5
作者 Vijay Naidu Jacqueline Whalley Ajit Narayanan 《Journal of Information Security》 2017年第4期296-327,共32页
Antiviral software systems (AVSs) have problems in identifying polymorphic variants of viruses without explicit signatures for such variants. Alignment-based techniques from bioinformatics may provide a novel way to g... Antiviral software systems (AVSs) have problems in identifying polymorphic variants of viruses without explicit signatures for such variants. Alignment-based techniques from bioinformatics may provide a novel way to generate signatures from consensuses found in polymorphic variant code. We demonstrate how multiple sequence alignment supplemented with gap penalties leads to viral code signatures that generalize successfully to previously known polymorphic variants of JS. Cassandra virus and previously unknown polymorphic variants of W32.CTX/W32.Cholera and W32.Kitti viruses. The implications are that future smart AVSs may be able to generate effective signatures automatically from actual viral code by varying gap penalties to cover for both known and unknown polymorphic variants. 展开更多
关键词 POLYMORPHIC Malware Variants Gap Penalties Syntactic Approach Pairwise SEQUENCE ALIGNMENT Multiple SEQUENCE ALIGNMENT Automatic signature generation Smith-Waterman Algorithm JS. Cassandra VIRUS W32.CTX/W32.Cholera VIRUS W32.Kitti VIRUS
下载PDF
Fast Confidentiality-Preserving Authentication for Vehicular Ad Hoc Networks 被引量:1
6
作者 MIRZAEE Siavash 蒋乐天 《Journal of Shanghai Jiaotong university(Science)》 EI 2019年第1期31-40,共10页
This paper studies the existing problems of message authentication protocols in vehicular ad hoc networks(VANETs) due to their significance in the future of commuting and transportation. Our contribution has been devo... This paper studies the existing problems of message authentication protocols in vehicular ad hoc networks(VANETs) due to their significance in the future of commuting and transportation. Our contribution has been devoted to implementing a new protocol for VANETs so that inherent security problems in past works are resolved. Exclusive security measures have been considered for the system which protects the users against threat of any attack. The new protocol shows a great hardness guaranteed by certificate based 80 bit security which assures messages to remain confidential in any time. Also, new unprecedented features like V2 X which improves system performance effectively have been instantiated. The simulation results indicate that message signature generation and verification both take place in much less time than present comparable rival protocols. 展开更多
关键词 MESSAGE AUTHENTICATION protocol vehicular ad HOC networks(VANETs) signature generation and verification
原文传递
Sequencing of 231 forensic genetic markers using the MiSeq FGxTM forensic genomics system-an evaluation of the assay and software 被引量:2
7
作者 Christian Hussing Christina Huber +3 位作者 Rajmonda Bytyci Helle S.Mogensen Niels Morling Claus Bφrsting 《Forensic Sciences Research》 2018年第2期111-123,共13页
The MiSeq FGx^(TM) Forensic Genomics System types 231 genetic markers in one multiplex polymerase chain reaction (PCR) assay.The markers include core forensic short tandem repeats (STRs) as well as identity,ancestry a... The MiSeq FGx^(TM) Forensic Genomics System types 231 genetic markers in one multiplex polymerase chain reaction (PCR) assay.The markers include core forensic short tandem repeats (STRs) as well as identity,ancestry and phenotype informative short nucleotide polymorphisms (SNPs).In this work,the MiSeq FGx^(TM) Forensic Genomics System was evaluated by analysing reproducibility,sensitivity,mixture identification and forensic phenotyping capabilities of the assay.Furthermore,the genotype calling of the ForenSeq^(TM) Universal Analysis Software was verified by analysing fastq.gz files from the MiSeq FGx^(TM) platform using the softwares STRinNGS and GATK.Overall,the performance of the MiSeq FGx^(TM) Forensic Genomics System was high.However,locus and allele drop-outs were relatively frequent at six loci (two STRs and four human identification SNPs) due to low read depth or skewed heterozygote balances,and the stutter ratios were larger than those observed with conventional STR genotyping methods.The risk of locus and allele drop-outs increased dramatically when the amount of DNA in the first PCR was lower than 250 pg.Two-person 50∶1 mixtures were identified as mixtures,whereas 100∶1 and 1000∶1 mixtures were not.Y-chromosomal short tandem repeats (Y-STRs) alleles were detected in the 100∶1 and 1000∶1 female/male mixtures.The ForenSeq^(TM) Universal Analysis Software provided the data analyst with useful alerts that simplified the analysis of the large number of markers.Many of the alerts were due to user-defined,locus-specific criteria.The results shown here indicated that the default settings should be altered for some loci.Also,recommended changes to the assay and software are discussed. 展开更多
关键词 Forensic science forensic genetics next generation sequencing short tandem repeats single nucleotide polymorphisms ForenSeq^(TM)DNA signature Prep Kit MiSeq FGx^(TM)Forensic Genomics System
原文传递
上一页 1 下一页 到第
使用帮助 返回顶部